KillNet: Russia's Cyber Militia Expands from DDoS to Data Theft Across NATO, Government, and Healthcare Targets

An in-depth threat actor review published by ThreatMon profiles KillNet — a pro-Russian hacktivist collective that emerged from the Russia-Ukraine war and grew into one of the largest organized cyber militia operations in the world, conducting distributed denial-of-service (DDoS) attacks, targeted intrusions, and credential theft operations against NATO member states, critical infrastructure, government systems, and healthcare organizations across Europe, North America, and Asia.

Origins: A Cyber Militia Born from Geopolitical Conflict

KillNet was formed from the merger of multiple pro-Russian hacker groups in response to the February 24, 2022 large-scale Russian invasion of Ukraine, with an explicit mandate to defend Russia on the cyber front. The group announced a cyber war against Ukraine and all nations supporting it, beginning with DDoS attacks against NATO members. Early operations in May 2022 targeted Romania following its expressions of support for Ukraine, causing Romanian government systems to experience days of outages. Italy was targeted in June 2022, with attacks progressing from website DDoS to the hacking of the Italian Senate and the Italian Automobile Club.

Recognizing that initial DDoS operations were producing insufficient strategic impact, KillNet issued a public call for cyber mobilization on Telegram, recruiting allied groups including f-CkNet, Zarya, RaHDiT, DPR Joker, ZSecnet, XaKNET, Beregini, CyberArmyRussia, Anonymous Russia, and others. The group subsequently reorganized into specialized sub-groups with close operational ties to Russian intelligence services and military units, transitioning from mass disruption to targeted attacks.

Major Operations: 2022–2023

KillNet's campaign record spans multiple high-profile targets across NATO countries and beyond:

KillMilk Credential Operation

A KillNet-affiliated operator known as KillMilk listed for sale 150 million passwords belonging to residents across Europe, the Americas, Ukraine, and other "unfriendly" countries — a dataset reportedly including bank account passwords, credit and debit card information, cryptocurrency account data, desktop access credentials from approximately 6,000 organizations worldwide, and government portal access.

Technical Profile

KillNet's primary technique remains volumetric DDoS against public-facing infrastructure across ports 21 (FTP), 80 (HTTP), 443 (HTTPS), and 22 (SSH), with documented brute-force activity against these services. Unlike technically sophisticated APT groups, KillNet's operational advantage comes from scale — a large, organized volunteer and recruited network with direct ties to Russian intelligence and military units — rather than novel exploit development. Targeted sectors include government, defense and weapons, healthcare, technology, and aviation/airport infrastructure across NATO member states.

Read the full analysis on IntelFusions